> For the complete documentation index, see [llms.txt](https://asus-isg-aidc.gitbook.io/guide/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://asus-isg-aidc.gitbook.io/guide/v1.4.0/cli/commandreference/firmwareupdate.md).

# Firmware Update

| Developer | Last modified |
| --------- | ------------- |
| AIDC Team | 2026/04/29    |

## Table of Contents

* [1. Overview](#overview)
* [2. BIOS Update](#bios-update)
  * [2.1 `bios-tool` — BIOS Update via Local Tool](#21-bios-tool--bios-update-via-local-tool)
  * [2.2 `bios-redfish-x86` — BIOS Update via Redfish (x86)](#22-bios-redfish-x86--bios-update-via-redfish-x86)
  * [2.3 `bios-redfish-arm` — BIOS Update via Redfish (ARM)](#23-bios-redfish-arm--bios-update-via-redfish-arm)
* [3. BMC Update](#bmc-update)
  * [3.1 `bmc-tool` — BMC Update via Local Tool](#31-bmc-tool--bmc-update-via-local-tool)
  * [3.2 `bmc-redfish` — BMC Update via Redfish](#32-bmc-redfish--bmc-update-via-redfish)
* [4. Mellanox Firmware Update](#mellanox-firmware-update)
  * [4.1 `mlnx-nic` — Mellanox NIC Firmware](#41-mlnx-nic--mellanox-nic-firmware)
  * [4.2 `mlnx-dpu` — Mellanox DPU Firmware](#42-mlnx-dpu--mellanox-dpu-firmware)
* [5. NVMe Firmware Update](#nvme-firmware-update)
  * [5.1 `nvme` — NVMe Firmware](#51-nvme--nvme-firmware)
* [6. Quick Summary](#quick-summary)
* [7. Usage Examples](#usage-examples)

***

## 1. Overview <a href="#overview" id="overview"></a>

The `fwupdate` command performs firmware updates on target nodes — covering BIOS, BMC, Mellanox NIC/DPU, and NVMe firmware. Multiple update methods are available depending on hardware architecture and access method.

```bash
aidc-cli fwupdate <subcommand> [flags]
```

{% hint style="danger" %}
Firmware updates carry risk of rendering hardware unresponsive if interrupted. Always verify firmware compatibility and ensure stable power/network before proceeding.
{% endhint %}

***

## 2. BIOS Update <a href="#bios-update" id="bios-update"></a>

### 2.1 `bios-tool` — BIOS Update via Local Tool

Updates BIOS firmware using an in-band tool. The firmware file must be placed in the `/firmware/bios` directory on the AIDC management node.

```bash
aidc-cli fwupdate bios-tool -f <firmware-file> [-r]
```

| Flag       | Short | Required | Description                                                   |
| ---------- | :---: | :------: | ------------------------------------------------------------- |
| `--file`   |  `-f` |     ✅    | BIOS firmware filename (placed in `/firmware/bios` directory) |
| `--reboot` |  `-r` |     ❌    | Reboot after update (default: false)                          |

{% hint style="info" %}
Place the BIOS firmware file (e.g., `.cap`) into the `/firmware/bios` directory before running this command.
{% endhint %}

***

### 2.2 `bios-redfish-x86` — BIOS Update via Redfish (x86)

Updates BIOS firmware on **x86** platforms via the Redfish API. Supports both local file upload (`locally`) and remote URI (`remotely`) as the firmware source.

**File format and update mode constraints:**

| File Format | Supported `--update-mode`      |
| ----------- | ------------------------------ |
| `.cap`      | `direct` **only**              |
| `.hpm`      | `staged` (default) or `direct` |

```bash
# Locally (upload file via Redfish)
aidc-cli fwupdate bios-redfish-x86 -a locally -f <firmware-file> -m <mode> [-p]

# Remotely (pull from URI via Redfish)
aidc-cli fwupdate bios-redfish-x86 -a remotely -u <uri> -m <mode> [--proto HTTP|HTTPS] [--file-user <user>] [--file-pwd <pwd>] [-p]
```

| Flag              | Short |  Default  | Required | Description                                                                                                                |
| ----------------- | :---: | :-------: | :------: | -------------------------------------------------------------------------------------------------------------------------- |
| `--update-action` |  `-a` | `locally` |     ❌    | Update source: `locally` (upload file) or `remotely` (URI)                                                                 |
| `--update-mode`   |  `-m` |  `staged` |    ❌\*   | Update timing: `staged` (apply on next reboot) or `direct` (immediate, forces poweroff). **`.cap` files require `direct`** |
| `--file`          |  `-f` |     —     |    ❌\*   | BIOS firmware filename `.cap`/`.hpm` (required when `--update-action locally`)                                             |
| `--uri`           |  `-u` |     —     |    ❌\*   | Remote firmware URI (required when `--update-action remotely`)                                                             |
| `--proto`         |   —   |   `HTTP`  |     ❌    | Transfer protocol for remote server: `HTTP` or `HTTPS`                                                                     |
| `--file-user`     |   —   |     —     |    ❌\*   | Username for remote file server (required when `--proto HTTPS`)                                                            |
| `--file-pwd`      |   —   |     —     |    ❌\*   | Password for remote file server (required when `--proto HTTPS`)                                                            |
| `--poweroff`      |  `-p` |  `false`  |     ❌    | Auto graceful shutdown via Redfish before update (forced `true` when `--update-mode direct`)                               |

{% hint style="danger" %}
**`.cap` files only support `--update-mode direct`.** The CLI default is `staged` — you must explicitly pass `-m direct` when using `.cap` files or the update will fail with an error.
{% endhint %}

{% hint style="warning" %}
`direct` mode forces a poweroff before applying firmware. Always use `--poweroff` (or ensure the node is already powered off) when using `direct` mode.
{% endhint %}

{% hint style="info" %}
For `locally`: place the `.cap` or `.hpm` file in the `/firmware/bios` directory on the AIDC management node. For `remotely` with HTTPS: both `--file-user` and `--file-pwd` must be provided.
{% endhint %}

***

### 2.3 `bios-redfish-arm` — BIOS Update via Redfish (ARM)

Updates BIOS firmware on **ARM** platforms via the Redfish API using local file upload. Accepted file format: `.fwpkg` only.

```bash
aidc-cli fwupdate bios-redfish-arm -f <firmware-file> [-m <mode>] [-p]
```

| Flag            | Short |  Default | Required | Description                                                                                  |
| --------------- | :---: | :------: | :------: | -------------------------------------------------------------------------------------------- |
| `--file`        |  `-f` |     —    |     ✅    | BIOS firmware filename `.fwpkg` (placed in `/firmware/bios` directory)                       |
| `--update-mode` |  `-m` | `staged` |     ❌    | Update timing: `staged` (apply on next reboot) or `direct` (immediate, forces poweroff)      |
| `--poweroff`    |  `-p` |  `false` |     ❌    | Auto graceful shutdown via Redfish before update (forced `true` when `--update-mode direct`) |

{% hint style="warning" %}
ARM platform only supports **local file upload** (no remote URI). Only `.fwpkg` files are accepted.
{% endhint %}

***

## 3. BMC Update <a href="#bmc-update" id="bmc-update"></a>

### 3.1 `bmc-tool` — BMC Update via Local Tool

Updates BMC firmware using a direct tool (non-Redfish). The firmware file must be placed in the `/firmware/bmc` directory on the AIDC management node.

```bash
aidc-cli fwupdate bmc-tool -f <firmware-file> [-p]
```

| Flag         | Short | Required | Description                                                 |
| ------------ | :---: | :------: | ----------------------------------------------------------- |
| `--file`     |  `-f` |     ✅    | BMC firmware filename (placed in `/firmware/bmc` directory) |
| `--preserve` |  `-p` |     ❌    | Preserve current BMC configuration (default: false)         |

{% hint style="info" %}
Place the BMC firmware file into the `/firmware/bmc` directory before running this command.
{% endhint %}

***

### 3.2 `bmc-redfish` — BMC Update via Redfish

Updates BMC firmware via the Redfish API. Supports both local file upload (`locally`) and remote URI (`remotely`) as the firmware source.

```bash
# Locally (upload file via Redfish)
aidc-cli fwupdate bmc-redfish -a locally -f <firmware-file> [-p]

# Remotely (pull from URI via Redfish)
aidc-cli fwupdate bmc-redfish -a remotely -u <uri> [--proto HTTP|HTTPS] [--file-user <user>] [--file-pwd <pwd>] [-p]
```

| Flag              | Short |  Default  | Required | Description                                                     |
| ----------------- | :---: | :-------: | :------: | --------------------------------------------------------------- |
| `--update-action` |  `-a` | `locally` |     ❌    | Update source: `locally` (upload file) or `remotely` (URI)      |
| `--file`          |  `-f` |     —     |    ❌\*   | BMC firmware filename (required when `--update-action locally`) |
| `--uri`           |  `-u` |     —     |    ❌\*   | Remote firmware URI (required when `--update-action remotely`)  |
| `--proto`         |   —   |   `HTTP`  |     ❌    | Transfer protocol for remote server: `HTTP` or `HTTPS`          |
| `--file-user`     |   —   |     —     |    ❌\*   | Username for remote file server (required when `--proto HTTPS`) |
| `--file-pwd`      |   —   |     —     |    ❌\*   | Password for remote file server (required when `--proto HTTPS`) |
| `--preserve`      |  `-p` |  `false`  |     ❌    | Preserve current BMC configuration                              |

{% hint style="info" %}
For `locally`: place the BMC firmware file in the `/firmware/bmc` directory on the AIDC management node. For `remotely` with HTTPS: both `--file-user` and `--file-pwd` must be provided.
{% endhint %}

***

## 4. Mellanox Firmware Update <a href="#mellanox-firmware-update" id="mellanox-firmware-update"></a>

### 4.1 `mlnx-nic` — Mellanox NIC Firmware

Updates Mellanox ConnectX NIC firmware. Only `.bin` files are accepted.

```bash
aidc-cli fwupdate mlnx-nic -f <firmware-file> [-r]
```

| Flag       | Short | Required | Description                          |
| ---------- | :---: | :------: | ------------------------------------ |
| `--file`   |  `-f` |     ✅    | Mellanox NIC firmware `.bin` file    |
| `--reboot` |  `-r` |     ❌    | Reboot after update (default: false) |

{% hint style="info" %}
Please ensure that the Mellanox `.bin` file downloaded from the official website (do not rename the file) is placed into the `/firmware/mlnx` directory. For Mellanox NIC firmware updates, it is required that the client system has either the Mellanox Firmware Tools (MFT) or the Mellanox OFED driver installed in advance.
{% endhint %}

{% hint style="warning" %}
Only `.bin` files are accepted for `mlnx-nic` (ConnectX/CX series). For BlueField DPU firmware (`.bfb`), use `mlnx-dpu` instead.
{% endhint %}

***

### 4.2 `mlnx-dpu` — Mellanox DPU Firmware

Updates Mellanox BlueField DPU firmware. Only `.bfb` files are accepted.

```bash
aidc-cli fwupdate mlnx-dpu -f <firmware-file> [-r]
```

| Flag       | Short | Required | Description                                             |
| ---------- | :---: | :------: | ------------------------------------------------------- |
| `--file`   |  `-f` |     ✅    | Mellanox DPU firmware `.bfb` file (BlueField/BF series) |
| `--reboot` |  `-r` |     ❌    | Reboot after update (default: false)                    |

{% hint style="info" %}
Please ensure that the Mellanox `.bfb` file downloaded from the official website (do not rename the file) is placed into the `/firmware/mlnx` directory. For Mellanox DPU firmware updates, it is required that the client system has either the Mellanox Firmware Tools (MFT) or the Mellanox DOCA driver installed in advance.
{% endhint %}

{% hint style="warning" %}
Only `.bfb` files are accepted for `mlnx-dpu` (BlueField/BF series). For ConnectX NIC firmware (`.bin`), use `mlnx-nic` instead.
{% endhint %}

***

## 5. NVMe Firmware Update <a href="#nvme-firmware-update" id="nvme-firmware-update"></a>

### 5.1 `nvme` — NVMe Firmware

Updates NVMe drive firmware. All flags are optional and fall back to settings configured via `aidc-cli init nvme-set`.

```bash
aidc-cli fwupdate nvme [-f <firmware-file>] [-d <device>]... [-r]
```

| Flag       | Short | Required | Description                                                                                          |
| ---------- | :---: | :------: | ---------------------------------------------------------------------------------------------------- |
| `--file`   |  `-f` |    ❌\*   | Override NVMe firmware filename (default: from `aidc-cli init nvme-get`)                             |
| `--device` |  `-d` |    ❌\*   | Override NVMe device path; repeat or comma-separate for multiple devices (default: from init config) |
| `--reboot` |  `-r` |     ❌    | Override reboot setting (default: from init config)                                                  |

{% hint style="info" %}
`fwupdate nvme` loads defaults from `aidc-cli init nvme-get`. At execution time, the resolved firmware file and target device list must both be present. Configure them first with `aidc-cli init nvme-set` or provide `--file` and `--device` on the command line.
{% endhint %}

{% hint style="warning" %}
Currently, only Samsung NVMe devices are confirmed to support firmware updates.
{% endhint %}

***

## 6. Quick Summary <a href="#quick-summary" id="quick-summary"></a>

| Subcommand         | Target       | Method                     | Key Flags                                                                                                         |
| ------------------ | ------------ | -------------------------- | ----------------------------------------------------------------------------------------------------------------- |
| `bios-tool`        | BIOS         | Local in-band tool         | `--file`, `--reboot`                                                                                              |
| `bios-redfish-x86` | BIOS (x86)   | Redfish (locally/remotely) | `--update-action`, `--update-mode` (**`direct` required for `.cap`**), `--file`, `--uri`, `--proto`, `--poweroff` |
| `bios-redfish-arm` | BIOS (ARM)   | Redfish (locally only)     | `--file`, `--update-mode`, `--poweroff`                                                                           |
| `bmc-tool`         | BMC          | Local tool                 | `--file`, `--preserve`                                                                                            |
| `bmc-redfish`      | BMC          | Redfish (locally/remotely) | `--update-action`, `--file`, `--uri`, `--proto`, `--preserve`                                                     |
| `mlnx-nic`         | Mellanox NIC | Tool                       | `--file` (`.bin`), `--reboot`                                                                                     |
| `mlnx-dpu`         | Mellanox DPU | Tool                       | `--file` (`.bfb`), `--reboot`                                                                                     |
| `nvme`             | NVMe         | Tool                       | `--file`, `--device`, `--reboot`                                                                                  |

***

## 7. Usage Examples <a href="#usage-examples" id="usage-examples"></a>

```bash
# Update BIOS with reboot (in-band tool)
aidc-cli fwupdate bios-tool -f "Z13PH-D16-OCP-ASUS-2601.CAP" -r

# Update x86 BIOS via Redfish — old-gen .cap (direct mode is mandatory)
aidc-cli fwupdate bios-redfish-x86 -a locally -f "Z13PH-D16-OCP-ASUS-2601.CAP" -m direct -p

# Update x86 BIOS via Redfish — new-gen .hpm (staged mode, apply on next reboot)
aidc-cli fwupdate bios-redfish-x86 -a locally -f "Z14PH-D16-ASUS-0401.hpm"

# Update x86 BIOS via Redfish — new-gen .hpm (direct mode — forces poweroff)
aidc-cli fwupdate bios-redfish-x86 -a locally -f "Z14PH-D16-ASUS-0401.hpm" -m direct

# Update x86 BIOS via Redfish (remotely, HTTP) — old-gen .cap
aidc-cli fwupdate bios-redfish-x86 -a remotely -u "http://192.168.1.100/firmware/bios.cap" -m direct

# Update x86 BIOS via Redfish (remotely, HTTP) — new-gen .hpm
aidc-cli fwupdate bios-redfish-x86 -a remotely -u "http://192.168.1.100/firmware/bios.hpm"

# Update x86 BIOS via Redfish (remotely, HTTPS with credentials) — old-gen .cap
aidc-cli fwupdate bios-redfish-x86 -a remotely -u "https://files.example.com/bios.cap" --proto HTTPS --file-user admin --file-pwd secret123 -m direct

# Update ARM BIOS via Redfish (locally only, .fwpkg required)
aidc-cli fwupdate bios-redfish-arm -f "NCPH-U0-ASUS-0403-NCH0009-24060701.fwpkg"

# Update ARM BIOS via Redfish (direct mode — forces poweroff)
aidc-cli fwupdate bios-redfish-arm -f "NCPH-U0-ASUS-0403-NCH0009-24060701.fwpkg" -m direct

# Update BMC firmware via local tool (preserve config)
aidc-cli fwupdate bmc-tool -f "R72324113.ima" -p

# Update BMC via Redfish (locally, preserve config)
aidc-cli fwupdate bmc-redfish -a locally -f "R72324113.ima" -p

# Update BMC via Redfish (remotely, HTTP public server)
aidc-cli fwupdate bmc-redfish -a remotely -u "http://192.168.1.100/firmware/R72324113.ima"

# Update BMC via Redfish (remotely, HTTPS private server)
aidc-cli fwupdate bmc-redfish -a remotely -u "https://files.example.com/R72324113.ima" --proto HTTPS --file-user admin --file-pwd secret123

# Update Mellanox NIC firmware (ConnectX, .bin file required)
aidc-cli fwupdate mlnx-nic -f "fw-ConnectX7-rel-28_42_1000-MCX75310AAS-HEA_Ax-UEFI-14.35.15-FlexBoot-3.7.500.signed.bin" -r

# Update Mellanox DPU firmware (BlueField, .bfb file required)
aidc-cli fwupdate mlnx-dpu -f "DOCA_2.9.1_BSP_4.9.1_Ubuntu_22.04-11.24-05.prod.bfb" -r

# Configure default NVMe firmware update settings
aidc-cli init nvme-set -f "General_PM9A3_U.2_GDC5A02Q_Noformat.bin" -d /dev/nvme0,/dev/nvme1 -r

# Update NVMe firmware using saved init settings (Samsung only)
aidc-cli fwupdate nvme

# Update NVMe firmware with explicit overrides
aidc-cli fwupdate nvme -f "General_PM9A3_U.2_GDC5A02Q_Noformat.bin" -d /dev/nvme0 -d /dev/nvme1 -r

# Post-update verification
aidc-cli chkfw all-version
```
